Palo_Alto_Networks
PSE-PLATFORM · Question #251
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A…
The correct answer is C. Untrust (Any) to DMZ (10.1.1.1), web-browsing -Allow D. Untrust (Any) to DMZ (10.1.1.1), ssh -Allow. Explanation/Reference:
NAT and Security Policy
Question
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.) Which two security policy rules will accomplish this configuration? (Choose two.)
Exhibit
Options
- AUntrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
- BUntrust (Any) to Untrust (10.1.1.1), ssh -Allow
- CUntrust (Any) to DMZ (10.1.1.1), web-browsing -Allow
- DUntrust (Any) to DMZ (10.1.1.1), ssh -Allow
- EUntrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow
How the community answered
(69 responses)- A28% (19)
- B6% (4)
- C55% (38)
- E12% (8)
Explanation
Explanation/Reference:
Topics
#DNAT#NAT policy#security policy zone matching#destination NAT
Community Discussion
No community discussion yet for this question.
